[gfx] Guard against possible race via gfxFontEntry::GetFontTable.

This commit is contained in:
Moonchild 2025-08-19 22:05:22 +02:00 • committed by roytam1
commit 7cadc57d49
2 changed files with 10 additions and 5 deletions

View file

@ -495,7 +495,7 @@ public:
private: private:
// The font table data block // The font table data block
nsTArray<uint8_t> mTableData; const nsTArray<uint8_t> mTableData;
// The blob destroy function needs to know the owning font entry // The blob destroy function needs to know the owning font entry
// so that it can hold the font-entry's reference while modifying the // so that it can hold the font-entry's reference while modifying the
@ -591,11 +591,16 @@ gfxFontEntry::ShareFontTableAndGetBlob(uint32_t aTag,
mFontTableCache = MakeUnique<nsTHashtable<FontTableHashEntry>>(8); mFontTableCache = MakeUnique<nsTHashtable<FontTableHashEntry>>(8);
} }
FontTableHashEntry *entry = mFontTableCache->PutEntry(aTag); FontTableHashEntry* entry;
if (MOZ_UNLIKELY(!entry)) { // OOM if (MOZ_UNLIKELY(entry = mFontTableCache->GetEntry(aTag))) {
return nullptr; // We must have been racing with another GetFontTable for the same table,
// and it won the race and filled in the entry before us.
// Ignore `aBuffer` in that case, and return a reference to the existing blob.
return entry->GetBlob();
} }
entry = mFontTableCache->PutEntry(aTag);
if (!aBuffer) { if (!aBuffer) {
// ensure the entry is null // ensure the entry is null
entry->Clear(); entry->Clear();

View file

@ -265,7 +265,7 @@ public:
// unregisters the table from the font entry. // unregisters the table from the font entry.
// //
// Pass nullptr for aBuffer to indicate that the table is not present and // Pass nullptr for aBuffer to indicate that the table is not present and
// nullptr will be returned. Also returns nullptr on OOM. // nullptr will be returned.
hb_blob_t *ShareFontTableAndGetBlob(uint32_t aTag, hb_blob_t *ShareFontTableAndGetBlob(uint32_t aTag,
nsTArray<uint8_t>* aTable); nsTArray<uint8_t>* aTable);